2026 Incident Cost Benchmarks: Cross-Source Aggregate
No single published source captures the complete picture of incident cost in 2026. The honest answer to "what does an incident cost?" depends on what kind of incident, in what sector, in what region, with what regulatory implications, and on whose definition of "cost." This page consolidates the major published 2024-2026 benchmarks across IBM, Verizon, Sophos, Coveware, FBI IC3, Resilience, and Mandiant, with explicit notes on what each measures and where they diverge. Use each source for its question; triangulate where you can; document your assumptions when you cannot.
The Master Benchmark Table
The single-table cross-source view. Each row is a published benchmark. The "Measure" column documents what is being counted; the "Source" column documents who published and when.
| Benchmark | Number | Measure | Source |
|---|---|---|---|
| Global average breach cost | $4.99M | All-cause breach across surveyed orgs (record high, +12% YoY) | IBM CODB 2026 |
| US average breach cost | $11.5M | US-headquartered surveyed orgs (highest of any country) | IBM CODB 2026 |
| Healthcare breach cost (highest sector) | $6.64M | Healthcare cohort average (down 10.5% YoY, still #1) | IBM CODB 2026 |
| Public sector breach cost (lowest sector) | $2.86M | Public sector cohort average (2025 edition, pending 2026 sector split) | IBM CODB 2025 |
| Ransomware mean recovery cost (cross-sector) | $1.53M | Recovery cost excluding ransom (down from $2.73M in 2024) | Sophos State of Ransomware 2025 |
| Ransomware mean recovery cost (healthcare) | $1.02M | Healthcare-specific recovery (down 60% from $2.57M in 2024) | Sophos State of Ransomware in Healthcare 2025 |
| Cross-sector median ransom payment | $150K | Coveware Q2 2026 (avg payment $1,880,612) | Coveware Q2 2026 |
| Healthcare mean ransom payment | $150K | Sophos healthcare cohort (down from $1.47M in 2024) | Sophos Healthcare 2025 |
| Ransomware payment rate | Record low | Q2 2026 new record low; data-exfiltration-only rate 15%; down from ~76% in 2019 | Coveware Q2 2026 |
| Median ransomware downtime | 16-24 days | From encryption event to operational restoration | Coveware quarterly |
| Insider threat (credential theft) | $779K | Cost per incident | Ponemon Cost of Insider Risks 2025 |
| P1 / Sev 1 incident cost | $794K | Average cost per P1 event | PagerDuty State of Digital Operations 2024 |
| Average BEC loss | ~$137K | Average loss per BEC complaint reported | FBI IC3 Internet Crime Report 2024 |
| Total IC3-reported cyber losses (US) | $16B+ | Calendar year 2024 reported | FBI IC3 2024 |
| Mean breach detection lifecycle | 247 days | Detection plus containment, cross-industry (up about 2.5% YoY) | IBM CODB 2026 |
| Cost reduction with AI/automation | -$1.93M avg | Versus orgs without extensive AI/automation | IBM CODB 2026 |
What Each Source Actually Measures
Apparent contradictions across published sources usually reflect different methodologies. The honest reading requires understanding what each source counts and what it excludes.
| Source | Methodology | Best For |
|---|---|---|
| IBM Cost of a Data Breach | Annual survey of approximately 600 organisations that experienced a breach; activity-based costing across four phases (detection/escalation, notification, post-breach response, lost business) | Per-breach average cost, sector and country breakouts, control-impact analysis |
| Verizon DBIR | Aggregates approximately 30,000 incidents annually from 100+ contributing organisations including law enforcement, insurance carriers, and IR firms | Breach-cause distribution, threat-actor analysis, attack-pattern frequency |
| Sophos State of Ransomware | Annual survey of approximately 5,000 IT and cybersecurity leaders globally | Ransomware attack rate, recovery cost, payment rate by sector and region |
| Coveware quarterly | Real cases Coveware handled as IR firm; not a survey, actual data from negotiations | Median ransom paid, downtime, payment rate, threat-actor distribution |
| Resilience Cyber Risk Report | Underwriter view; claims data and policy-portfolio analysis | Insurance-claim severity by control posture; underwriting-relevant view |
| FBI IC3 Internet Crime Report | Voluntary complaints filed at ic3.gov; necessarily underrepresents actual losses | Reported cyber-crime totals, BEC losses, scam categorisation |
| Mandiant M-Trends | Mandiant's IR engagement data; nation-state and APT focus | Dwell time, attack-vector distribution, threat-actor TTPs |
| Ponemon Cost of Insider Risks | Annual survey of approximately 1,000 organisations on insider-risk experience | Insider incident cost by category (negligent, malicious, credential theft) |
| PagerDuty State of Digital Operations | Survey of operations leaders; incident-management focus | Per-P1-incident cost; on-call practice trends |
The 2025-2026 Year-Over-Year Story
The prior-year story was a 9% decline in IBM's CODB headline, the first drop in the report's history. IBM CODB 2026 (released 29 July 2026) reversed it: the global average rose 12% to a record $4.99M, and the mean detection-and-containment lifecycle lengthened about 2.5% to 247 days. IBM attributes the turnaround largely to AI-enabled attacks, one in four malicious breaches were AI-enabled and cost about $6M each on average, roughly $1M above the overall average. AI and automation still cut cost for defenders that deploy it extensively (about $1.93M saved per breach), but that saving no longer offsets the rising attack side. The US average climbed to $11.5M, more than double the global figure.
Several other 2024-2026 trends are visible across multiple sources. Ransomware payment rates remain historically low (Coveware reports the payment rate fell to a new record low in Q2 2026, with the data-exfiltration-only rate down to 15%, and down from 76% in 2019), driven by improved backups, OFAC compliance, and customer/regulator preference. Median ransom amounts fell further in Q2 2026 (Coveware median $150,000, down about 50% on the quarter) even as average payments jumped to $1,880,612 on a handful of very large law-firm settlements: Sophos reports average recovery cost dropped to $1.53M in 2025 from $2.73M in 2024, a 44% decline, as fewer victims pay and more restore from backups.
Identity-platform and supply-chain compromises (Okta 2022/2023, CircleCI 2023, Snowflake-related 2024, MOVEit 2023) continue to produce ecosystem-scale damage that no single benchmark captures cleanly. The 2026 cost picture for these incident types is probably best estimated as 5-15x the directly-reported provider-side cost, given the customer-of-customer cleanup work that ripples through the ecosystem.
How to Use These Benchmarks
Three rules of thumb for using published incident-cost benchmarks responsibly.
- Anchor to your sector and size, not the global mean. The IBM CODB 2026 headline of $4.99M is an aggregate across an extremely heterogeneous population. For a 1,000-employee mid-market SaaS company, the more relevant anchor is the technology-sector average ($4.79M, IBM CODB 2025 edition) adjusted by size cohort. For a small county government, anchor to the public-sector average ($2.86M, 2025 edition) adjusted by size and known municipal-ransomware comparables.
- Use multiple sources for the same question. If you are estimating ransomware exposure, look at IBM CODB ransomware-specific data, Sophos ransomware-specific recovery cost, Coveware median ransom, and Mandiant M-Trends dwell-time data. Triangulate; do not pick one number and treat it as truth.
- Document your assumptions. Loss-given-incident estimates that go into capital-planning, cyber insurance buying, or board-level risk reporting should explicitly cite which benchmarks were used, why they were chosen, and what adjustments were applied. Defensible methodology matters more than precise numbers.